Cross-site scripting in HTML Sanitizer - CVE-2026-47345
Published: June 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in HTML serialization of namespace attributes when processing sanitized HTML content. A remote attacker can supply specially crafted input to execute arbitrary script in a victim's browser.
The issue allows bypassing the cross-site scripting prevention mechanism.
Affected software
TYPO3
How to mitigate CVE-2026-47345
TYPO3 - addressed in versions 10.4.57, 11.5.51, 12.4.46, 13.4.31, 14.3.3